Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
165 changes: 56 additions & 109 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,119 +1,66 @@
[![Build Status](https://travis-ci.org/ntop/n2n.png?branch=dev)](https://travis-ci.org/ntop/n2n)


# n2n

n2n is a light VPN software which makes it easy to create virtual networks bypassing intermediate firewalls.

In order to start using n2n, two elements are required:

- A _supernode_: it allows edge nodes to announce and discover other nodes. It must have a port publicly accessible on internet.
- _edge_ nodes: the nodes which will be a part of the virtual networks

A virtual network shared between multiple edge nodes in n2n is called a _community_. A single supernode can relay multiple communities and a single computer can be part of multiple communities at the same time. An encryption key can be used by the edge nodes to encrypt the packets within their community.

n2n tries to establish a direct peer-to-peer connection via udp between the edge nodes when possible. When this is not possible (usually due to special NAT devices), the supernode is also used to relay the packets.


## Quick Setup

Some Linux distributions already provide n2n as a package so a simple `sudo apt install n2n` will do the work. Alternatively, up-to-date packages for most distributions are available on [ntop repositories](http://packages.ntop.org/).

On host1 run:
<!-- by 文荣平 -->
### Quick Setup
- **Installation Method**: In some Linux distributions, `n2n` is provided as a software package, and you can install it using `sudo apt install n2n`. Additionally, the latest software packages for most distributions can be obtained from [ntop repositories](http://packages.ntop.org/).
- **Example Configuration**: Here are examples of configuring edge nodes on different hosts:

```sh
$ sudo edge -c mynetwork -k mysecretpass -a 192.168.100.1 -f -l supernode.ntop.org:7777
# Run the edge command with sudo privileges to configure an n2n edge node
# -c specifies the community name as mynetwork
# -k specifies the encryption key as mysecretpass
# -a specifies the local IP address as 192.168.100.1
# -f runs the process in foreground mode
# -l specifies the supernode to connect to as supernode.ntop.org:7777
```

On host2 run:

- Host 1:
```sh
$ sudo edge -c mynetwork -k mysecretpass -a 192.168.100.2 -f -l supernode.ntop.org:7777
sudo edge -c mynetwork -k mysecretpass -a 192.168.100.1 -f -l supernode.ntop.org:7777
```

Now the two hosts can ping each other.

**IMPORTANT** It is strongly advised to choose a custom community name (`-c`) and a secret encryption key (`-k`) in order to prevent other users from connecting to your computer. For the privacy of your data sent and to reduce the server load of `supernode.ntop.org`, it is also suggested to set up a custom supernode as explained below.


## Setting up a Custom Supernode

You can create your own infrastructure by setting up a supernode on a public server (e.g. a VPS). You just need to open a single port (1234 in the example below) on your firewall (usually `iptables`).

1. Install the n2n package
2. Edit `/etc/n2n/supernode.conf` and add the following:
```
-p=1234
```
3. Start the supernode service with `sudo systemctl start supernode`
4. Optionally enable supernode start on boot: `sudo systemctl enable supernode`

Now the supernode service should be up and running on port 1234. On your edge nodes you can now specify `-l your_supernode_ip:1234` to use it. All the edge nodes must use the same supernode.


## Manual Compilation

On Linux, compilation from source is straight forward:

- Host 2:
```sh
./autogen.sh
./configure
make

# optionally install
make install
sudo edge -c mynetwork -k mysecretpass -a 192.168.100.2 -f -l supernode.ntop.org:7777
```

For Windows, MacOS, optimizations and general building options, please check out [Building documentation](doc/Building.md) for compilation and running.

**IMPORTANT** It is generally recommended to use the [latest stable release](https://github.com/ntop/n2n/releases). Please note that the current _dev_ branch usually is not guaranteed to be backward compatible neither with the latest stable release nor with previous _dev_ states. On the other hand, if you dare to try bleeding edge features, you are encouraged to compile from _dev_ – just keep track of sometimes rapidly occuring changes. Feedback in the _Issues_ section is appreciated.


## Security Considerations

When payload encryption is enabled (provide a key using `-k`), the supernode will not be able to decrypt
the traffic exchanged between two edge nodes but it will know that edge A is talking with edge B.

The choice of encryption schemes that can be applied to payload has recently been enhanced. Please have
a look at [Crypto description](doc/Crypto.md) for a quick comparison chart to help make a choice. n2n edge nodes use
AES encryption by default. Other ciphers can be chosen using the `-A_` option.

A benchmark of the encryption methods is available when compiled from source with `tools/n2n-benchmark`.

The header which contains some metadata like the virtual MAC address of the edge nodes, their IP address, their real
hostname and the community name optionally can be encrypted applying `-H` on the edges.


## Advanced Configuration

More information about communities, support for multiple supernodes, routing, traffic restrictions and on how to run an edge as
a service is available in the [more detailed documentation](doc/Advanced.md).


## Contribution

You can contribute to n2n in various ways:

- Update an [open issue](https://github.com/ntop/n2n/issues) or create a new one with detailed information
- Propose new features
- Improve the documentation
- Provide pull requests with enhancements

For details about the internals of n2n check out the [Hacking guide](https://github.com/ntop/n2n/blob/dev/doc/Hacking.md).


## Further Readings and Related Projects

Answers to frequently asked questions can be found in our [FAQ document](https://github.com/ntop/n2n/blob/dev/doc/Faq.md).

Here is a list of third-party projects connected to this repository:

- Collection of pre-built binaries for Windows: [lucktu](https://github.com/lucktu/n2n)
- n2n for Android: [hin2n](https://github.com/switch-iot/hin2n)
- Docker images: [Docker Hub](https://hub.docker.com/r/supermock/supernode/)
- Go bindings, management daemons and CLIs for n2n edges and supernodes, Docker, Kubernetes & Helm Charts: [pojntfx/gon2n](https://pojntfx.github.io/gon2n/)
- Windows GUI (along with a custom version of n2n) but also working with regular n2n: [HappyNet](https://github.com/happynclient/happynwindows)

---
After the configuration is completed, the two hosts can ping each other. It is highly recommended to choose a custom community name (`-c`) and a secret encryption key (`-k`) to prevent other users from connecting to your computer. To protect data privacy and reduce the server load of `supernode.ntop.org`, it is also recommended to set a custom supernode.

I. Community and Encryption Key Settings
1. Custom Community and Key
To prevent other users from connecting to your computer, it is strongly recommended to select a custom community name (using the -c parameter) and a secure encryption key (using the -k parameter) for each virtual network. Avoid using default or easily guessable community names and keys to ensure the privacy and security of the network.
2. Key Strength
The length and complexity of the encryption key will affect the security of the encryption. When setting the encryption key, try to use a key that is long and contains multiple character types (letters, numbers, special characters). A longer key can increase the difficulty of cracking and improve the security of data transmission.
II. Security of Supernode Usage
1. Custom Supernode
To protect data privacy and reduce the server load of public supernodes (such as supernode.ntop.org), it is recommended to set a custom supernode. Follow these steps to set it up:
Install the n2n package.
Edit the /etc/n2n/supernode.conf file and add a listening port, for example, -p = 1234.
Start the supernode service using sudo systemctl start supernode.
Optionally, use sudo systemctl enable supernode to make the supernode start automatically when the system boots.
2. Port Security
When setting up a custom supernode, you need to open the specified port (such as port 1234 in the above example) on the firewall (usually iptables). Ensure that only the necessary ports are opened and appropriate access control is carried out on the ports to prevent unauthorized access.
III. Data Encryption
1. Payload Encryption
When payload encryption is enabled (by providing a key using the -k parameter), the supernode will not be able to decrypt the traffic exchanged between the two edge nodes, but it will still know which edge nodes are communicating. This means that although the data content is protected, the communication topology information is still visible.
2. Encryption Scheme Selection
The n2n edge nodes use AES encryption by default. You can select other encryption schemes according to your needs and specify them using the -A_ option. Different encryption schemes may vary in terms of security, performance, etc. It is recommended to refer to the comparison chart in the Crypto description and select a suitable encryption scheme according to the actual situation.
3. Encryption Benchmark Testing
If you compile n2n from the source code, you can use tools/n2n-benchmark to conduct benchmark tests on different encryption methods to understand their performance and find a balance between security and performance.
IV. Header Encryption
Metadata Protection
The header of the edge node contains some metadata, such as the virtual MAC address, IP address, real host name, and community name. To protect the privacy of this metadata, you can use the -H option on the edge node to encrypt the header and prevent the leakage of this information.
V. Authentication and Authorization
1. User/Password Authentication
When using the user/password-based authentication method, the supernode needs to be prepared accordingly. Configure the user and password information in the community.list file. If a user changes their password or you need to prohibit a user from accessing the community, you need to update or delete the corresponding lines in the community.list file and restart the supernode or send the reload_communities command to the management port to make the changes take effect.
2. Management Port Authentication
For command operations on the management port, there is a simple authentication mechanism. Read operations are generally allowed, while write operations may require providing the correct authentication password. The basic authentication logic is implemented in the mgmt_auth function, which determines whether to authorize by comparing the password hash value in the request with the provided authentication password hash value. Ensure that a secure management port password is set to prevent unauthorized management operations.
VI. Version and Update
1. Use of Stable Version
It is generally recommended to use the latest stable version. The current dev branch usually does not guarantee backward compatibility with the latest stable version or the previous dev state. If you want to try new features, you can compile from the dev branch, but you need to pay attention to tracking the changes that may occur quickly and provide feedback in the Issues section.
2. Timely Update
Regularly check for updates of n2n and install the latest version in a timely manner to obtain security patches and functional improvements to ensure the security and stability of the software.
VII. Code Security
1. Open Source Code Review
Since n2n is open source software, you can review the source code to understand its implementation details and potential security risks. In particular, carefully review the code sections related to key functions such as encryption, authentication, and network communication.
2. Security of Dependent Libraries
n2n may depend on some external libraries, such as OpenSSL. Ensure that the versions of these dependent libraries are secure and update the dependent libraries with security vulnerabilities in a timely manner.
By following the above security precautions, you can improve the security of the n2n virtual network and protect the privacy of data transmission and network communication.

(C) 2007-22 - ntop.org and contributors
71 changes: 71 additions & 0 deletions README.zh.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@

<!-- by 文荣平 -->
### 快速设置
- **安装方式**:部分Linux发行版已将 `n2n` 作为软件包提供,可使用 `sudo apt install n2n` 进行安装。此外,大多数发行版的最新软件包可在 [ntop repositories](http://packages.ntop.org/) 中获取。
- **示例配置**:在不同主机上配置边缘节点的示例如下:
```sh



# 以sudo权限运行edge命令,配置n2n边缘节点
# -c 参数指定社区名称为 mynetwork
# -k 参数指定加密密钥为 mysecretpass
# -a 参数指定本地IP地址为 192.168.100.1
# -f 参数表示以前台模式运行
# -l 参数指定连接到的超级节点为 supernode.ntop.org:7777

```
- 主机1:
```sh
sudo edge -c mynetwork -k mysecretpass -a 192.168.100.1 -f -l supernode.ntop.org:7777
```

- 主机2:
```sh
sudo edge -c mynetwork -k mysecretpass -a 192.168.100.2 -f -l supernode.ntop.org:7777
```

配置完成后,两台主机可以相互ping通。强烈建议选择自定义社区名称(`-c`)和秘密加密密钥(`-k`),以防止其他用户连接到您的计算机。为保护数据隐私、减少 `supernode.ntop.org` 的服务器负载,还建议设置自定义超级节点。


一、社区与加密密钥设置
1. 自定义社区与密钥
为防止其他用户连接到你的计算机,强烈建议为每个虚拟网络选择自定义的社区名称(使用 -c 参数)和安全的加密密钥(使用 -k 参数)。避免使用默认或简单易猜的社区名和密钥,以确保网络的私密性和安全性。
2. 密钥强度
加密密钥的长度和复杂度会影响加密的安全性。在设置加密密钥时,尽量使用较长且包含多种字符类型(字母、数字、特殊字符)的密钥。较长的密钥可以增加破解的难度,提高数据传输的安全性。
二、超级节点使用安全
1. 自定义超级节点
为了保护数据隐私并减轻公共超级节点(如 supernode.ntop.org)的服务器负载,建议设置自定义的超级节点。按照以下步骤进行设置:
安装 n2n 包。
编辑 /etc/n2n/supernode.conf 文件,添加监听端口,例如 -p=1234。
使用 sudo systemctl start supernode 启动超级节点服务。
可选择使用 sudo systemctl enable supernode 使超级节点在系统启动时自动启动。
2. 端口安全
在设置自定义超级节点时,需要在防火墙(通常是 iptables)上开放指定的端口(如上述示例中的 1234 端口)。确保仅开放必要的端口,并对端口进行适当的访问控制,防止未经授权的访问。
三、数据加密
1. 有效载荷加密
当启用有效载荷加密(通过 -k 参数提供密钥)时,超级节点将无法解密两个边缘节点之间交换的流量,但它仍能知道哪些边缘节点正在通信。这意味着虽然数据内容得到了保护,但通信的拓扑信息仍然可见。
2. 加密方案选择
n2n 边缘节点默认使用 AES 加密。你可以根据需求选择其他加密方案,使用 -A_ 选项指定。不同的加密方案在安全性、性能等方面可能存在差异。建议参考 Crypto description 中的比较图表,根据实际情况选择合适的加密方案。
3. 加密基准测试
如果从源代码编译 n2n,可以使用 tools/n2n-benchmark 对不同的加密方法进行基准测试,以了解它们的性能表现,从而在安全性和性能之间找到平衡。
四、头部加密
元数据保护
边缘节点的头部包含一些元数据,如虚拟 MAC 地址、IP 地址、真实主机名和社区名称等。为了保护这些元数据的隐私,可以在边缘节点上使用 -H 选项对头部进行加密,防止这些信息被泄露。
五、认证与授权
1. 用户 / 密码认证
在使用用户 / 密码基于的认证方式时,超级节点需要进行相应的准备。在 community.list 文件中配置用户和密码信息。如果用户更改密码或需要禁止某个用户访问社区,需要更新或删除 community.list 文件中的相应行,并重启超级节点或向管理端口发送 reload_communities 命令,使更改生效。
2. 管理端口认证
对于管理端口的命令操作,有简单的认证机制。读取操作通常允许,而写入操作可能需要提供正确的认证密码。在 mgmt_auth 函数中实现了基本的认证逻辑,通过比较请求中的密码哈希值与提供的认证密码哈希值来判断是否授权。确保设置安全的管理端口密码,防止未经授权的管理操作。
六、版本与更新
1. 使用稳定版本
一般建议使用最新稳定版本。当前的 dev 分支通常不保证与最新稳定版本或以前的 dev 状态向后兼容。如果要尝试新功能,可以从 dev 分支编译,但需要注意跟踪可能快速发生的变化,并在 Issues 部分提供反馈。
2. 及时更新
定期检查 n2n 的更新,及时安装最新版本,以获取安全补丁和功能改进,确保软件的安全性和稳定性。
七、代码安全
1. 开源代码审查
由于 n2n 是开源软件,你可以审查源代码以了解其实现细节和潜在的安全风险。特别是涉及加密、认证、网络通信等关键功能的代码部分,需要仔细审查。
2. 依赖库安全
n2n 可能依赖于一些外部库,如 OpenSSL 等。确保这些依赖库的版本是安全的,及时更新存在安全漏洞的依赖库。
通过遵循以上安

Binary file added ai_usage_screenshots/2205308050315_1.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added ai_usage_screenshots/2205308050315_2.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added ai_usage_screenshots/2205308050320_1.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added ai_usage_screenshots/2205308050320_2.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added ai_usage_screenshots/2205308050320_3.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added ai_usage_screenshots/2205308050346_1.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added ai_usage_screenshots/2205308050346_2.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added ai_usage_screenshots/2205308050346_3.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
2 changes: 2 additions & 0 deletions modification_log.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
![alt text](ai_usage_screenshots/2205308050315_1.png)
![alt text](ai_usage_screenshots/2205308050315_2.png)
Loading